¸ßͨоƬQualPwn·ì϶£»GoogleºÍNASAÒòJira·þÎñÆ÷ÅäÖÃÃýÎóµ¼ÖÂÃô¸ÐÊý¾Ýй¶

°ä²¼¹¦·ò 2019-08-06
1¡¢×êÑÐÍŶӰ䲼Sextortionڲƭ»î¶¯»ã±¨£¬³¬¹ý2ÒÚÓʼþÕË»§³ÉΪָ±ê


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cofense LabsÔÚ6Ô·ݷ¢ÏÖÒ»¸öÖØÒª·Ö·¢sextortionڲƭÓʼþµÄ½©Ê¬ÍøÂ磬¸Ã½©Ê¬ÍøÂçûÓÐÊÔͼ´ÓÊÜϰȾµÄÍÆËã»úÖÐÇÔȡеÄÊý¾Ý¼¯£¬¶øÊdzÁ¸´ÀûÓÃ֮ǰй¶µÄÊý¾Ý¼¯¡£ÕâЩÊý¾Ý¼¯×îÔç¿É×·ÒäÖÁ10Äêǰ£¬Æ¾¾Ý×êÑÐÈËÔ±°ä²¼µÄÊý¾Ý¿â£¬¹²Óг¬¹ý2ÒÚ¸öµç×ÓÓʼþÕË»§³ÉΪ¸Ã½©Ê¬ÍøÂçµÄ¹¥»÷Ö¸±ê¡£Cofense»¹ÆÀ¹À³Æ½ñÄêsextortion»î¶¯µÄ±ÈÌØ±ÒÇ®°üÒѾ­½Ó¹Üµ½Á˳¬¹ý150ÍòÃÀÔªµÄ¸¶¿î¡£


Ô­ÎÄÁ´½Ó£ºhttps://cofense.com/cofense-labs-publishes-database-200-million-compromised-accounts-targeted-sextortion-email-campaigns/


2¡¢CafePressÔâºÚ¿Í¹¥»÷£¬³¬¹ý2300ÍòÓû§µÄÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Êý¾ÝÐ¹Â¶Í¨ÖªÍøÕ¾HIBP³ÆCafePressÓÚ2019Äê2ÔÂÔâµ½ºÚ¿ÍÈëÇÖ£¬³¬¹ý2300ÍòÓû§µÄÓ×ÎÒÐÅϢй¶¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬µç×ÓÓʼþµØÖ·¡¢ÐÕÃû¡¢ÃÜÂë¡¢µç»°ºÅÂëÒÔ¼°×¡Ö·¡£Æ¾¾Ý°²È«×êÑÐÔ±Jim ScottµÄ±íÊö£¬½üÒ»°ëµÄÓû§ÃÜÂëÊÇͨ¹ýbase64 SHA1±àÂëµÄ£¬ÕâÊÇÒ»¸ö½ÏÈõµÄ¼ÓÃÜËã·¨£¬ÁíÒ»°ëÓû§ÔòÊÇͨ¹ýFacebookºÍÑÇÂíÑ·µÈµÚÈý·½ÁîÅÆ½øÐеǼ¡£BleepingComputer·¢ÏÖÔ¼49.3Íò¸öCafePressÕË»§Êý¾ÝÔÚºÚ¿ÍÂÛ̳ÉÏÏúÊÛ£¬Ä¿Ç°Éв»Ã÷ÏÔËüÃÇÊÇ·ñÓëͳһÊÂÎñÓйØ¡£½ØÖÁĿǰCafePressÉÐδ°ä²¼ÈκÎÉêÃ÷»ò֪ͨ£¬µ«Óû§ÔڵǼʱ±»Ç¿ÔìÒªÇó³ÁÖÃÃÜÂë¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.forbes.com/sites/daveywinder/2019/08/05/cafepress-hacked-23m-accounts-compromised-is-yours-one-of-them/#1c5b34a7407e


3¡¢PresbyterianÔâºÚ¿ÍÈëÇÖ£¬½ü18.3Íò»¼ÕßÐÅϢй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


PresbyterianÒ½ÁÆ·þÎñÖÐÐÄÔÚÆä²¿ÃÅÔ±¹¤Êܵ½´¹µö¹¥»÷ºóÔâ·êÊý¾Ýй¶ÊÂÎñ£¬Æ¾¾Ý¸ÃÒ½ÁÆÖÐÐİ䲼µÄ²¼¸æ£¬¹²Óнü18.3Íò»¼ÕßµÄÐÅϢй¶£¬Ô̺¬ËûÃǵÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂëÒÔ¼°ÁÙ´²ÐÅÏ¢µÈ¡£¸ÃÊÂÎñ²úÉúÔÚ5ÔÂ9ÈÕ×óÓÒ£¬PresbyterianÓÚ6ÔÂ6ÈÕ¼ì²âµ½ÁËÕâÒ»ÊÂÎñ¡£¸ÃÒ½ÁÆÖÐÐÄËæ¼´Í¨ÖªÁËÁª¹ú·¨Âɲ¿ÃŲ¢·¢Õ¹½øÒ»²½µÄµ÷²é¡£ÎªÁËÔ¤·À´ËÀàÊÂÎñÔٴβúÉú£¬Presbyterian²ÉÈ¡Á˸ü¶à°²È«´ëÊ©±£»¤ÆäÓʼþϵͳ£¬²¢¶ÔÔ±¹¤½øÐÐÇ¿ÔìÐÔ°²È«Åàѵ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.phs.org/Pages/data-security.aspx


4¡¢Aegon Life¹ÙÍø´æÔÚ·ì϶£¬µ¼ÖÂ1ÍòÃû¿Í»§µÄÒþÖÔй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¡¶È±£ÏÕ¹«Ë¾Aegon Life¹ÙÍø´æÔÚ·ì϶£¬µ¼ÖÂ×î¶à1ÍòÃû¿Í»§µÄÓ×ÎÒÊý¾Ý¿ÉÄÜй¶¡£ÕâЩÊý¾ÝÔ̺¬ÐÕÃû¡¢´ºÇï¡¢ÐÔ±ð¡¢ÊÖ»úºÅÂëÒÔ¼°ÄêÊÕÈë¡¢½¡È«Õ½ÊõµÈÐÅÏ¢¡£¸Ã·ì϶¼«¶Èµ¥Ò»£¬µ±Óû§µÇ¼Aegon Life¹ÙÍøÊ±£¬ÆäÌîÈëµÄÓ×ÎÒÉí·ÝÐÅÏ¢²¢Ã»Óеõ½³ä·Ö±£»¤£¬ÀýÈçÓû§ÔÚÁªÏµ±í¸ñ¡¢¸÷Àà±£ÏÕ¹æ»®ÍÆË㹤¾ßÖÐÌîÈëµÄÐÅÏ¢¡£ÔÚ7ÔÂÖÐÑ®½Óµ½·ì϶»ã±¨ºó£¬¸Ã¹«Ë¾ÒѾ­½¨¸´ÁË·ì϶¡£Ä¿Ç°Éв»Ã÷ÏÔÊÇ·ñÓÐÈκοͻ§Êý¾ÝÔâµ½ÀÄÓá£


Ô­ÎÄÁ´½Ó£ºhttps://thewire.in/tech/aegon-life-insurance-data-leak


5¡¢GoogleºÍNASAÒòJira·þÎñÆ÷ÅäÖÃÃýÎóµ¼ÖÂÃô¸ÐÊý¾Ýй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


JiraÊÇÒ»¸öÊ¢ÐеÄÏîÄ¿ÖÎÀí½â¾ö¹æ»®£¬°²È«×êÑÐÔ±Avinash Jain·¢ÏÖµ±ÔÚJira CloudÖд´½¨ÐµÄfilterºÍdashboardʱ£¬ÆäĬÈϿɼûÐÔÊÇ¡°ËùÓÓ×±£¬ÕâºÜÈÝÒ×±»Àí½âΪ¡°ÆóÒµÄÚ²¿ËùÓÐÈË¡±µ«ÏÖʵÉÏËüÖ¸µÄÊÇ¡°»¥ÁªÍøÉϵÄËùÓÐÈË¡±¡£ÕâÖÖÅäÖÃÃýÎóʹµÃºÜ¶à×éÖ¯µÄÃô¸ÐÏîÄ¿ÐÅÏ¢ÆØ¹â£¬Ô̺¬Google¡¢Yahoo¡¢NASA¡¢Lenovo¡¢1Password¡¢ZendeskÒÔ¼°µ±¾Ö»ú¹¹µÈ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/misconfigured-jira-servers-leak-info-on-users-and-projects/


6¡¢¸ßͨоƬ´æÔÚQualPwn·ì϶£¬²¨¼°æçÁú855µÈ¶à¿îSoC

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¸ßͨ¶à¿îSoCÊܵ½Á½¸ö·ì϶µÄÓ°Ï죬ÕâÁ½¸ö·ì϶±»³ÆÎªQualPwn£¬±ðÀëÊÇÓ°Ïì¸ßͨWLAN×é¼þ¼°AndroidÄں˵Ļº³åÇøÒç¶Âí½Å£¨CVE-2019-10538£©ÒÔ¼°¸ßͨWLAN¼°Modem¹Ì¼þÖеĻº³åÇøÒç¶Âí½Å£¨CVE-2019-10540£©¡£Æ¾¾Ý¸ßͨ°ä²¼µÄ°²È«²¼¸æ£¬ºóÕßÓ°ÏìµÄ²úÆ·Ô̺¬SD 820¡¢SD 835¡¢SD 845¡¢SD 850¡¢SD 855µÈ20¶à¿îоƬ¡£¸ßͨºÍAndroidÍŶÓÒѾ­°ä²¼ÁËÓйؽ¨¸´²¹¶¡¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/qualpwn-vulnerabilities-in-qualcomm-chips-let-hackers-compromise-android-devices/